logo

Shai Hulud 2.0 Compromises 1,200+ Organizations, Exposing Critical Runtime Secrets

ID: 7e8e2901-a2a0-5f85-96da-a350bd4bdd89

STIX ID: report--7e8e2901-a2a0-5f85-96da-a350bd4bdd89

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-11-28

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Shai Hulud 2.0 is a sophisticated npm supply-chain worm detected on 2025-11-24 that compromised approximately 1,195 organizations by publishing attacker-controlled packages which ran preinstall payloads to capture double-base64-encoded memory snapshots and exfiltrate in-memory secrets from developer machines, CI/CD pipelines, self-hosted GitHub runners, and cloud build servers—resulting in theft of GitHub personal access tokens, AWS/GCP keys, blockchain tokens, and Slack API keys many of which remained valid days after the breach and prompting urgent recommendations to rotate non-human credentials and treat runtime environments as fully compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.